The Security screen gathers your organisation's account-protection settings in one place: how strictly people must use multi-factor authentication (MFA) when they sign in, which verification methods they can choose from, and how single sign-on connects to your identity provider. Only administrators can open it, and nothing takes effect until you save.
The security screen
Open the Security screen from Setup. It holds three groups of settings: the enforcement policy for multi-factor authentication, the allowed verification methods, and single sign-on.


The Discard and Save changes buttons stay inactive until you change a setting. Adjust the controls you need, then choose Save changes to apply them across your organisation, or Discard to drop your edits and return to the last saved state.
If your organisation signs in through an identity provider, the single sign-on area lets you connect it — you pick the protocol, set the default role that provisioned members receive, and decide whether your provider satisfies MFA on its own.
MFA enforcement
The enforcement policy decides whether people must protect their account with a second factor when they sign in. Select one of three levels:
- Optional — users can choose whether to enable MFA.
- Soft enforcement — users see a banner prompting them to set up MFA until a deadline you set.
- Hard enforcement — users are blocked until they set up MFA.
One level applies at a time. Where your organisation uses single sign-on, you can also decide whether your identity provider satisfies MFA or whether Pyron requires a second factor as well.
Allowed methods
Each verification method has its own switch, so you control which second factors people can use:
- Authenticator app — an app such as Google Authenticator or Authy.
- SMS verification — codes sent by text message.
- Email verification — codes sent by email.
- Passkey / security key — a passkey or hardware security key.
For how members set up and manage each of these, see the MFA methods reference.